VYPR

CWE-416

Use After Free

VariantStableLikelihood: High

Description

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (8,274)

page 106 of 414
  • CVE-2021-38005HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-43539HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects…

  • CVE-2021-43535HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-38504HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-37998HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37997HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21900HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.02

    A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-38496HigNov 3, 2021
    risk 0.57cvss 8.8epss 0.02

    During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and…

  • CVE-2021-37993HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in PDF Accessibility in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37988HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Profiles in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who convinced a user to engage in specific gestures to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37987HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Network APIs in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37985HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had convinced a user to allow for connection to debugger to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37983HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dev Tools in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37982HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Incognito in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37977HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30809HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-37974HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37970HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37962HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37961HigOct 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Tab Strip in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.